CFR A.I CyberSecurity Scoring
CFR
Company Information
Website:http://www.cfr.org
Employees number:2,156
Number of followers:399,097
NAICS:54172
Industry Type:Think Tanks
Homepage:cfr.org
CFR Risk Score (AI oriented)
Between 750 and 799
CFRThink Tanks
Updated:
03/04/2026
03/04/2026
769/1000
Fair
Baa
CFR Global Score (TPRM)
xxxx
CFRThink Tanks
Score locked

CFRFair
Current Score
769Baa (FAIR)
01000
2 incidents
-8 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
754
AUGUST 2026
769
JULY 2026
769
JUNE 2026
769
MAY 2026
769
APRIL 2026
769
Vulnerability
07 Apr 2026 • CFR
TP-Link: Russian APT28 Hackers Hijack Routers to Steal Credentials
Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign
768
CRITICAL-1
TP-1775579951
Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign
The UK’s National Cyber Security Centre (NCSC) has issued a warning about two ongoing cyberespionage campaigns by the Russian hacking group APT28 (also known as Fancy Bear, Forest Blizzard, and Sofacy), which is linked to Russia’s GRU military intelligence unit. Since early 2024, APT28 has been hijacking vulnerable internet routers particularly TP-Link models to redirect traffic through attacker-controlled servers and steal credentials from targeted organizations.
### How the Attack Works
APT28 has repurposed virtual private servers (VPS) as malicious DNS servers, intercepting high volumes of DNS requests from compromised routers. The group employs an opportunistic approach, initially casting a wide net to identify potential victims before narrowing down targets of intelligence value.
In one campaign, APT28 exploited CVE-2023-50224, a vulnerability in TP-Link WR841N routers that allows unauthenticated attackers to extract credentials via crafted HTTP requests. By altering the DHCP DNS settings on these routers, the group forced downstream devices (such as laptops and phones) to resolve requests through their malicious servers. This enabled adversary-in-the-middle (AitM) attacks, allowing APT28 to harvest passwords, OAuth tokens, and other credentials from web and email services.
Microsoft Threat Intelligence further reported that APT28 and its sub-group Storm-2754 have been compromising SOHO routers since at least August 2023, expanding their infrastructure to facilitate these attacks.
### Impact and Attribution
The NCSC assesses that APT28’s operations are highly targeted, focusing on entities of strategic interest to Russian intelligence. While the initial router compromises appear broad, the group refines its focus at later stages to prioritize high-value victims. The stolen credentials could enable further unauthorized access, though the exact scope of follow-on attacks remains unclear.
This campaign underscores the persistent threat posed by state-backed cyber actors leveraging common vulnerabilities in consumer-grade networking devices to conduct large-scale espionage.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
769
FEBRUARY 2026
769
JANUARY 2026
769
Cyber Attack
01 Jan 2026 • CFR
FBI: Russia used social engineering to breach prominent messaging accounts, Ukraine says
Russian Cyber Espionage Campaign Targets Government, Military, and Activists Across Ukraine, Europe, and the U.S.
754
CRITICAL-15
FBI1782484133
Russian Cyber Espionage Campaign Targets Government, Military, and Activists Across Ukraine, Europe, and the U.S.
Ukraine’s Security Service (SBU), in collaboration with the FBI, has uncovered a prolonged Russian cyber espionage campaign aimed at compromising the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the United States. The operation, designed to extract sensitive military, political, and economic intelligence, also sought to steal victims’ personal data.
Rather than exploiting vulnerabilities in messaging apps, attackers relied on social engineering tactics. One common method involved sending fraudulent text messages often in the early morning posing as official support services to trick users into revealing account credentials. The SBU noted that victims were particularly vulnerable during these hours due to fatigue or distraction.
Targets included Ukrainian government institutions, public officials, activists, and civilians, though the SBU did not disclose the specific Russian intelligence service behind the campaign, the primary messaging platforms affected, or the total number of victims. The FBI has not yet commented on the investigation.
The disclosure aligns with previous warnings from Ukraine and Western intelligence agencies about Russian efforts to infiltrate secure messaging platforms. Earlier this year, Dutch authorities reported a global campaign by Russian state-backed hackers to hijack Signal and WhatsApp accounts belonging to government, diplomatic, and military personnel, often by impersonating customer support to obtain verification codes or PINs.
Ukraine has repeatedly documented Russian espionage operations targeting military communications, including malware designed to steal data and attempts to extract encrypted Telegram and Signal messages from devices recovered on the battlefield.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
769
NOVEMBER 2025
769
OCTOBER 2025
769
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CFR ??
What was CFR's A.I Rankiteo Cyber Score in August 2026 ??
What was CFR's A.I Rankiteo Cyber Score in July 2026 ??
What was CFR's A.I Rankiteo Cyber Score in June 2026 ??
What was CFR's A.I Rankiteo Cyber Score in May 2026 ??
What was CFR's A.I Rankiteo Cyber Score in April 2026 ??
What was CFR's A.I Rankiteo Cyber Score in March 2026 ??
What was CFR's A.I Rankiteo Cyber Score in February 2026 ??
What was CFR's A.I Rankiteo Cyber Score in January 2026 ??
What was CFR's A.I Rankiteo Cyber Score in December 2025 ??
What was CFR's A.I Rankiteo Cyber Score in November 2025 ??
What was CFR's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on CFR's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CFR ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CFR's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?